FRAMEWORK .legal | NIS2 Framework

NIS2 compliance framework dashboard showing risk management requirements Articles 20-21, 23, 27, 29, 30 with real-time tracking for essential and important entities
NIS2 framework customization interface allowing essential and important entities to select applicable articles and chapters for tailored compliance strategy

NIS2 FRAMEWORK Navigate NIS2 compliance with confidence

The NIS2 Directive sets comprehensive requirements for risk management, incident handling and cybersecurity in critical sectors. We have mapped all requirements from Articles 20-21, 23, 27, 29 and 30 into clear, action-oriented frameworks with automated compliance tracking and integration with your existing security standards.

  • Complete NIS2 framework covering all minimum risk management requirements
  • Select only requirements that apply to your organisation – save time and resources
  • Real-time compliance tracking shows exactly where you stand with NIS2
  • Reuses existing ISO 27001 and GDPR tasks – avoid duplicate work

NIS2 Framework - Including Specialised Energy Sector Solution:

Our NIS2 Framework covers all directive requirements, with a dedicated, extended framework for the energy sector that goes beyond the general minimum requirements.

  • For all sectors: NIS2 Directive For all essential and important entities. Covers minimum requirements in Articles 20-21 and 23 regarding risk management, incident handling, supply chain security, business continuity and registration (Articles 27, 29, 30).
  • Specifically for the energy sector: NIS2 Energy For organisations in the Danish energy sector covered by Executive Order No. 260 of 6 March 2025. Extended framework with 21 thematic chapters and level-based implementation (levels 1-5) for organisational preparedness, physical security and cybersecurity.
NIS2 covered sectors including energy, transport, health, financial services, digital infrastructure, and cloud computing with essential and important entity classification

NIS2 FRAMEWORK Tailor your NIS2 compliance strategy

Our NIS2 Framework maps all relevant requirements, but not every rule applies to every organisation. Customise your compliance approach efficiently:

How to design your framework:

  • Identify whether you are an essential or important entity

  • Find relevant chapters that affect your business

  • Focus on applicable articles to prioritise compliance efforts

  • Assess risk and impact for strategic implementation

Who Is Covered By NIS2?

You are covered by NIS2 if you are an essential or important entity in critical sectors (energy, transport, health, financial sector, digital infrastructure, etc.), provide digital services such as cloud computing, or operate critical infrastructure in Denmark.

Specifically for the energy sector: If your organisation is covered by Executive Order No. 260 on resilience and preparedness in the energy sector, you must meet both the NIS2 Directive's minimum requirements and the sector-specific controls defined in the order.

NIS2 framework integration with ISO 27001, GDPR, CIS18, and CER Directive showing 60-70% overlap and reusable compliance documentation

NIS2 FRAMEWORK Leverage synergies with existing compliance frameworks

The NIS2 Framework integrates seamlessly with your existing compliance programmes. Avoid duplication and maximise the value of your current investments:

Framework Synergies:

  • The same security controls can meet multiple requirements simultaneously

  • Documentation and processes can be reused across frameworks

  • Investment in one area strengthens compliance on multiple fronts

  • Less duplication of work and resources

Examples of overlapping frameworks:

  • ISO 27001 Many companies start with ISO 27001 as the foundation for NIS2 compliance. Information security management and risk management directly support NIS2's requirements for technical and organisational security measures.
  • GDPR Personal data protection and processing security overlap with NIS2's requirements for data protection and breach handling, particularly when handling personal data in security incidents.
  • CIS18 Practical cybersecurity controls from CIS Controls implement many of the technical measures NIS2 requires, from asset and access management to incident response.
  • CER Directive For the energy sector, critical infrastructure requirements from the CER Directive supplement NIS2's cybersecurity focus with physical security measures and emergency planning.

Our Customers

  • +400

    companies

  • +10.000

    users

  • +79.000

    contracts

  • +14.000

    processing activities

Statements top swirl
Statements bottom swirl

.legal Compliance Hub

Read all about .legals compliance on our compliance hub.

+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Vestforbrænding
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
ARP Hansen
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell